An issue was discovered on Tenda AC15 V15.03.1.16_multi devices. A remote, unauthenticated attacker can gain remote code execution on the device with a crafted password parameter for the COOKIE header.
- https://www.exploit-db.com/exploits/44253/
- https://www.fidusinfosec.com/remote-code-execution-cve-2018-5767/
- https://github.com/ARPSyndicate/cvemon
- https://github.com/Scorpion-Security-Labs/CVE-2018-5767-AC9
- https://github.com/db44k/CVE-2018-5767-AC9